Software Productivity Solutions, Inc. (SPS) proposes an innovative approach - called the Forensic Analysis and Collection System (FACS) - to provide an unprecedented level of accuracy, ease-of-use, and overall effectiveness in collecting, recovering ,and analyzing computer forensic data. Our effort will investigate, define, and develop methods and supporting tools for collecting and analyzing forensic evidence. These methods and tools will be combined into a documented process that guides the user through the task of gathering and analyzing computer forensic data from an intrusion/crime scene without worry of destroying or contaminating important evidence. Our post-mortem forensic methods and tools will assist the user in determining: 1) how an intrusion was accomplished, 2) what computing resources and data were affected, 3) what damage was done to the computing environment, and 4) what must be done to recover from the event. We will leverage recovery work done by SPS, George Mason University, and other IWT Recovery IPT members by defining a logical flow from computer forensic analysis to recovery using techniques developed by the IPT.